Bitcoin9 min read
Bitcoin address types: 1, 3, bc1q and bc1p explained
The first characters of a Bitcoin address tell you how coins sent to it are locked, what they will cost to spend later and which software can pay it. Here are the four formats in use today, checked against the BIPs that define them.
Short answer: Bitcoin has four address types in everyday use. Addresses starting with 1 are legacy P2PKH, 3 are P2SH (multisig or wrapped SegWit), bc1q are native SegWit and bc1p are Taproot. All four are valid on the Bitcoin network and can pay one another. What differs is the fee to spend coins received at each type, the checksum and case rules, and whether older software can send to it: some wallets and exchanges still reject bc1p.
What are the four Bitcoin address formats?
Each prefix stands for one kind of output script. Apart from the original P2PKH, each one was defined in a Bitcoin Improvement Proposal (BIP) and switched on by a soft fork.
| Prefix | Type and encoding | Defined in, year |
|---|---|---|
1 | Legacy (P2PKH); Base58Check | Original software, 2009 |
3 | Script hash (P2SH), for multisig or nested SegWit; Base58Check | BIP16, BIP13; 2012 |
bc1q | Native SegWit v0 (P2WPKH or P2WSH); Bech32 | BIP141, BIP173; 2017 |
bc1p | Taproot, SegWit v1 (P2TR); Bech32m | BIP341, BIP350; 2021 |
BIP16 enforces P2SH in blocks timestamped from 1 April 2012, and BIP13 defines the 3 address format for it. SegWit activated in August 2017. Taproot activated at block 709,632 in November 2021, the height set by the activation parameters in Bitcoin Core 0.21.1.
A 3 address commits only to the hash of a script, so the address alone does not show what is behind it. It might be a 2-of-3 multisig vault or a single-key wallet using nested SegWit (P2SH-P2WPKH). The two look the same until the coins are spent.
Length is a second clue. A 1 address is up to 34 characters long and a 3 address is 34. For bc1q, 42 characters means a single key (P2WPKH) and 62 means a script such as multisig (P2WSH). A bc1p address is always 62 characters.
How can you tell which address you have?
Prefix, case and checksum
1and3use Base58Check. These addresses are case-sensitive, and the alphabet leaves out 0, O, I and l so that they cannot be confused. A built-in checksum makes almost any typo produce an invalid address, including a change of case.bc1addresses use bech32 or bech32m.bcis the mainnet prefix and1is a separator; the characters after it never include 1, b, i or o. BIP173 says an address must be all lowercase or all uppercase, never mixed. Uppercase exists for QR codes, where it allows alphanumeric mode, which BIP173 puts at 45% more compact than byte mode.- Bech32 has a stronger checksum. BIP173 guarantees that it detects any error affecting up to 4 characters, with less than a 1 in 109 chance of missing larger errors. BIP350 then fixed one weakness: inserting or deleting
qcharacters just before a finalpleft a bech32 checksum valid. Version 0 addresses are protected by their fixed lengths, so they stay on bech32. Version 1 and later, starting with Taproot, use bech32m.
A checksum proves that the string was not mistyped. It does not prove that it is the address you meant. A look-alike address pasted from your history passes every checksum, which is how address poisoning works.
xpub, ypub, zpub and derivation paths
A wallet generated from a seed phrase derives each address type along its own path. If you restore a seed and see a zero balance, the new wallet is usually scanning a different path from the old one.
| Standard and path | Addresses | Extended public key |
|---|---|---|
BIP44m/44'/0'/0' | 1 (P2PKH) | xpub |
BIP49m/49'/0'/0' | 3 (P2WPKH nested in P2SH) | ypub |
BIP84m/84'/0'/0' | bc1q (P2WPKH) | zpub |
BIP86m/86'/0'/0' | bc1p (single-key P2TR) | xpub (no new prefix) |
The ypub and zpub prefixes come from SLIP-0132, a SatoshiLabs registry, not from a BIP. BIP86 defines no prefix of its own, so a Taproot account is exported as an ordinary xpub. Many newer wallets export output descriptors such as wpkh(…) or tr(…) instead, which name the script type rather than hinting at it through a prefix.
Can any Bitcoin address send to any other?
Yes. The address type belongs to the output being created, not to the sender. A wallet holding coins at a 1 address can pay a bc1p address, and a Taproot wallet can pay a 1 address; the transaction simply has inputs of one type and outputs of another. Payments to bc1q have been safe since SegWit activated in 2017, and to bc1p since Taproot activated in November 2021.
The limit is the sending software, which has to understand the address encoding. Bech32 (bc1q) is widely supported. Bech32m (bc1p) came later, and BIP350 deliberately made software that only knows bech32 reject Taproot addresses as invalid. The BIP calls this break intentional: it shields existing senders from the checksum weakness described above, at the cost of old software refusing to pay Taproot addresses. Bitcoin Core gained the ability to pay Taproot addresses in 0.21.1, and before activation Bitcoin Optech urged every wallet and service that pays user-supplied addresses to add bech32m sending.
Exchange support is harder to pin down. The community-maintained Bech32 adoption page on the Bitcoin Wiki tracks it, but entries for large exchanges are not always current. Treat the withdrawal form as the real test: if it calls a bc1p address invalid, that platform cannot send to it yet. Give it a bc1q address from the same wallet instead. Nothing is lost, because nothing was sent. For moving coins off a platform in general, see withdrawing crypto to your own wallet.
Why does the address type change the fee?
Bitcoin fees are priced per virtual byte (vbyte) of transaction data. Most of a transaction's size comes from its inputs, the coins being spent, and each input's size is set by the type of address those coins were received at. Bitcoin Optech's Preparing for taproot series gives these sizes for single-signature wallets:
| Type | Output | Input | 2 inputs, 2 outputs |
|---|---|---|---|
P2PKH (1) | 34 | 148 | 374 |
P2WPKH (bc1q) | 31 | 68 | 208.5 |
P2TR key path (bc1p) | 43 | 57.5 | 211.5 |
Nested SegWit sits in between. In Optech Newsletter #42, a transaction with one input and two outputs is 220 vbytes when it spends P2PKH, 167 vbytes for P2SH-P2WPKH and 141 vbytes for P2WPKH. At an example fee rate of 10 sat/vB, one input costs 1,480 sats to spend from a 1 address, 680 from bc1q and 575 from bc1p.
- You save when you spend, not when you receive. Coins received at a legacy address cost more to move later, and the gap grows with every input. Many small payments to one old address make an expensive consolidation.
- Paying a Taproot address costs the sender a little more. Its output is 43 vbytes against 31 for
bc1q. In Optech's two-in, two-out example the totals differ by 3 vbytes, so for a simple single-key wallet neither type is clearly cheaper. - Taproot's larger savings are for shared control. A multisig that signs through the key path produces one signature, with the same on-chain footprint as a single-key spend. A
3multisig has to reveal its whole script and every required signature.
How fee rates move with demand, and why a low-fee payment waits longer, is covered in how long a Bitcoin transaction takes.
What does Taproot change for privacy, and what does it not?
BIP341 describes Taproot outputs as spendable by a key or, optionally, a script, and indistinguishable from each other: as long as the key path is used, nobody learns whether a script path existed. Schnorr signatures (BIP340) make it possible for several signers to combine their keys and signatures into one, so a jointly controlled wallet can spend like a single signer. If the key path cannot be used, only the script branch that is actually executed is revealed, not the other spending conditions.
What Taproot does not change matters just as much:
- Amounts and addresses stay public, and the chain of transactions can still be followed from one address to the next.
- Reusing a
bc1paddress links your payments exactly as reusing any other address does. - A script-path spend reveals that a script path existed and that the key path was not used. According to BIP341, the depth of the script in the tree also leaks information.
To hide amounts and counterparties you need a different chain altogether. What that involves is covered in swapping Bitcoin to Monero privately.
Which addresses on other chains look like Bitcoin's?
Several coins derived from Bitcoin use the same address formats, sometimes byte for byte. A checksum cannot help here, because the string is valid on both chains.
| Network | Prefixes | Overlap with Bitcoin mainnet |
|---|---|---|
| Bitcoin testnet | tb1, m or n, 2 (regtest bcrt1) | None, but test coins have no value and a mainnet service should reject these addresses |
| Litecoin | L, M, ltc1, ltcmweb1, older 3 | 3: Litecoin Core 0.14.2 added M for P2SH but kept 3 valid |
| Bitcoin Cash | q… or p… after bitcoincash: (CashAddr), legacy 1 and 3 | Legacy 1 and 3 are the same format as Bitcoin's |
| Dogecoin | D, 9 or A | None: Dogecoin Core uses its own version bytes |
Bitcoin SV also uses 1 addresses. The practical rules:
- Copy the address from the receive screen of the exact coin you are sending, never from a note or from memory.
- Prefer
bc1qorbc1pfor Bitcoin. Thebcprefix is not used by Litecoin (ltc), by Bitcoin Cash (bitcoincash:) or by testnet (tb), so a wrong-chain paste fails validation. - Use CashAddr for Bitcoin Cash, and
L,Morltc1for Litecoin, so neither can be mistaken for a Bitcoin address. - BTC on Ethereum is a different asset. Wrapped bitcoin is a token at a
0xaddress, not a Bitcoin address; see wrapped vs native crypto.
If BTC does go to a 1 or 3 address that came from a Bitcoin Cash or Litecoin wallet, the coins sit on the Bitcoin chain under keys that the other wallet controls. Whoever holds that wallet's keys can sometimes recover them by importing the keys into a Bitcoin wallet. If the address belongs to an exchange, recovery depends on that exchange.
Which Bitcoin address should you use for a swap on Ghostex?
The BTC payout field on Ghostex accepts all four mainnet formats: 1 (P2PKH), 3 (P2SH), bc1q (P2WPKH or P2WSH) and bc1p (P2TR). It checks the checksum and the bech32 or bech32m variant, turns down testnet addresses, and tells you when a string looks like another network's address, such as a Litecoin ltc1 address. It cannot tell a Bitcoin Cash legacy address from a Bitcoin one, because the two formats are identical. And as the Terms (section 10) put it, a valid format does not prove that the address is yours or that your wallet supports the asset.
- Payout. Ghostex covers the network fee on the payout, so the address type does not change your quote. It changes what you pay later: BTC received at
bc1qorbc1pcosts less to spend than at a1address. A3multisig vault works too. - Refund. If a swap cannot complete, the deposit comes back automatically, in the coin you sent, minus the network cost of sending it, to your refund address or, if you left that field empty, to the address you paid from. If you pay from an exchange account, add a refund address of your own. How automatic refunds work covers the details.
- Deposit. Send the exact amount shown on your order within the 30-minute window. A typical swap takes 5 to 30 minutes, most of it the deposit confirming; a deposit paid in BTC needs 2 confirmations.
- Lightning. BTC over Lightning is a separate payout option that takes a Lightning invoice, Lightning address, LNURL or BOLT12 offer rather than an on-chain address. See Lightning vs on-chain Bitcoin.
To get BTC from another coin, start from a pair page such as ETH to BTC, LTC to BTC or BCH to BTC. There is no account and no ID check, and the flat 0.48% fee is already in the quote.
This guide is general information about how Bitcoin addresses work, not financial advice. Protocol facts follow the BIPs and sources linked above; product facts follow the Terms and the Privacy policy.
FAQ
Bitcoin address questions
Which Bitcoin address type should I use?
For a single-key wallet, bc1q (native SegWit) or bc1p (Taproot). Both are cheaper to spend from than 1 or 3 addresses. More sending software supports bc1q; bc1p has the smallest inputs, but some platforms still cannot send to it.
Can I send Bitcoin from a bc1q address to a 1 or 3 address?
Yes. Any Bitcoin address type can pay any other, because the type only describes how the receiving output is locked. The sending software must understand the destination's encoding, which matters mainly for bc1p.
Why does my exchange say a bc1p address is invalid?
Its withdrawal software does not support bech32m (BIP350), the encoding of Taproot addresses. The rejection is by design, so nothing is sent. Use a bc1q address from the same wallet instead.
Are Bitcoin addresses case-sensitive?
Addresses starting with 1 or 3 are: changing the case of one character makes them invalid. Addresses starting with bc1 are not, but they must be all lowercase or all uppercase, never mixed. Uppercase is used in QR codes.
Is an address starting with 3 always multisig?
No. A 3 address is P2SH: it commits to the hash of a script, which can be a multisig or a single key wrapped in SegWit (P2SH-P2WPKH). The address alone does not show which.
Does Ghostex accept Taproot (bc1p) addresses for BTC payouts?
Yes. The BTC payout field accepts bc1p, bc1q, 1 and 3 mainnet addresses and turns down testnet ones. A valid format does not prove the address is yours, so copy it from your own wallet.
Keep reading
More guides
How long a Bitcoin transaction takes
About 10 minutes per block, so 1 to 6 confirmations take 10 to 60 minutes. What slows a transaction down, and how to speed it up.
Read the guideLightning vs on-chain Bitcoin
Lightning is fast and cheap for smaller amounts; on-chain settles anything and everything. Here is how each behaves in a swap, and when to receive your BTC over Lightning instead.
Read the guideNetwork fees on a swap, explained
The fee to send a deposit, the fee to receive a payout, and the flat 0.48% exchange fee. Here is who charges what, and how to keep the network cost down.
Read the guide